Splunk IT Service Intelligence

kvstore_to_json.py missing -l option for partial ITSI object restore

amartin6
Path Finder

Using ITSI 4.3.0, attempting to do a partial restore via CLI, referencing https://docs.splunk.com/Documentation/ITSI/4.1.0/Configure/kvstore_to_json.pyoperations#Perform_a_pa...

The kvstore_to_json.py file is missing the -l option that is used to specify the path for the rules file, tried with a one and capital L , but neither of those options are in the file either, also looked/grepped for the word "rule" out of the python file but doesn't exist.

[splunk~]$ bin/splunk cmd python etc/apps/SA-ITOA/bin/kvstore_to_json.py -u admin -p ourpassword -f $SPLUNK_HOME/var/itsi/backups/manualbkps/Aug2 -l etc/apps/SA-ITOA/bin/rules.json -i -d -y -n
Usage: kvstore_to_json.py [options]

kvstore_to_json.py: error: no such option: -l
[splunk~]$

The documentation specifies partial restores can only be done via CLI and not GUI, I went back through the document to version 4.1.0 and its not a new feature, just missing? https://docs.splunk.com/Documentation/ITSI/latest/Configure/BackupandRestoreITSIconfig

0 Karma
1 Solution

amartin6
Path Finder

Feature removed in 4.3:
The old partial backup/restore options from the CLI were removed in ITSI 4.3.0 and was deprecated in 4.2.0.
https://docs.splunk.com/Documentation/ITSI/4.3.0/ReleaseNotes/Removedfeatures

View solution in original post

0 Karma

amartin6
Path Finder

Feature removed in 4.3:
The old partial backup/restore options from the CLI were removed in ITSI 4.3.0 and was deprecated in 4.2.0.
https://docs.splunk.com/Documentation/ITSI/4.3.0/ReleaseNotes/Removedfeatures

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...